2022 CVE Vulnerabilities
27,552 CVEs published in 2022.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2022-34750 | HIGH | 7.5 | 1.2% | Jun 28, 2022 | An issue was discovered in MediaWiki through 1.38.1. The lemma length of a Wikibase lexeme is currently capped at a thou... |
| CVE-2022-30997 | HIGH | 7.2 | 1.4% | Jun 28, 2022 | Use of hard-coded credentials vulnerability exists in STARDOM FCN Controller and FCJ Controller R4.10 to R4.31, which ma... |
| CVE-2022-30707 | HIGH | 8.8 | 0.6% | Jun 28, 2022 | Violation of secure design principles exists in the communication of CAMS for HIS. Affected products and versions are CE... |
| CVE-2022-29519 | HIGH | 7.5 | 0.4% | Jun 28, 2022 | Cleartext transmission of sensitive information vulnerability exists in STARDOM FCN Controller and FCJ Controller R1.01 ... |
| CVE-2022-23896 | MEDIUM | 5.4 | 0.5% | Jun 28, 2022 | Admidio 4.1.2 version is affected by stored cross-site scripting (XSS). |
| CVE-2022-0624 | HIGH | 7.3 | 0.9% | Jun 28, 2022 | Authorization Bypass Through User-Controlled Key in GitHub repository ionicabizau/parse-path prior to 5.0.0. |
| CVE-2022-34134 | HIGH | 8.8 | 0.4% | Jun 28, 2022 | Jorani v1.0 was discovered to contain a Cross-Site Request Forgery (CSRF) via the component /application/controllers/Use... |
| CVE-2022-34133 | MEDIUM | 6.1 | 0.5% | Jun 28, 2022 | Jorani v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the Comment parameter at applicatio... |
| CVE-2022-34132 | CRITICAL | 9.8 | 1.5% | Jun 28, 2022 | Jorani v1.0 was discovered to contain a SQL injection vulnerability via the id parameter at application/controllers/Leav... |
| CVE-2022-31104 | MEDIUM | 5.6 | 1.6% | Jun 28, 2022 | Wasmtime is a standalone runtime for WebAssembly. In affected versions wasmtime's implementation of the SIMD proposal fo... |
| CVE-2022-33009 | MEDIUM | 4.8 | 0.6% | Jun 27, 2022 | A stored cross-site scripting (XSS) vulnerability in LightCMS v1.3.11 allows attackers to execute arbitrary web scripts ... |
| CVE-2022-32995 | CRITICAL | 9.8 | 15.9% | Jun 27, 2022 | Halo CMS v1.5.3 was discovered to contain a Server-Side Request Forgery (SSRF) via the template remote download function... |
| CVE-2022-32994 | CRITICAL | 9.8 | 16.7% | Jun 27, 2022 | Halo CMS v1.5.3 was discovered to contain an arbitrary file upload vulnerability via the component /api/admin/attachment... |
| CVE-2022-31103 | HIGH | 7.5 | 1.4% | Jun 27, 2022 | lettersanitizer is a DOM-based HTML email sanitizer for in-browser email rendering. All versions of lettersanitizer belo... |
| CVE-2022-31101 | HIGH | 8.8 | 24.1% | Jun 27, 2022 | prestashop/blockwishlist is a prestashop extension which adds a block containing the customer's wishlists. In affected v... |
| CVE-2022-31099 | MEDIUM | 6.5 | 0.9% | Jun 27, 2022 | rulex is a new, portable, regular expression language. When parsing untrusted rulex expressions, the stack may overflow,... |
| CVE-2022-33879 | LOW | 3.3 | 1.9% | Jun 27, 2022 | The initial fixes in CVE-2022-30126 and CVE-2022-30973 for regexes in the StandardsExtractingContentHandler were insuffi... |
| CVE-2022-33007 | HIGH | 8.8 | 0.8% | Jun 27, 2022 | TRENDnet Wi-Fi routers TEW751DR v1.03 and TEW-752DRU v1.03 were discovered to contain a stack overflow via the function ... |
| CVE-2022-32092 | CRITICAL | 9.8 | 5.6% | Jun 27, 2022 | D-Link DIR-645 v1.03 was discovered to contain a command injection vulnerability via the QUERY_STRING parameter at __aja... |
| CVE-2022-31100 | MEDIUM | 6.5 | 0.8% | Jun 27, 2022 | rulex is a new, portable, regular expression language. When parsing untrusted rulex expressions, rulex may crash, possib... |
| CVE-2022-31098 | HIGH | 7.5 | 1.1% | Jun 27, 2022 | Weave GitOps is a simple open source developer platform for people who want cloud native applications, without needing K... |
| CVE-2022-31096 | MEDIUM | 5.7 | 0.5% | Jun 27, 2022 | Discourse is an open source discussion platform. Under certain conditions, a logged in user can redeem an invite with an... |
| CVE-2022-31093 | HIGH | 7.5 | 1.6% | Jun 27, 2022 | NextAuth.js is a complete open source authentication solution for Next.js applications. In affected versions an attacker... |
| CVE-2022-31092 | HIGH | 8.1 | 1.3% | Jun 27, 2022 | Pimcore is an Open Source Data & Experience Management Platform. Pimcore offers developers listing classes to make query... |
| CVE-2022-31091 | HIGH | 7.7 | 1.4% | Jun 27, 2022 | Guzzle, an extensible PHP HTTP client. `Authorization` and `Cookie` headers on requests are sensitive information. In af... |
Check if your code is affected by 2022 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now